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In the Claims ; 

1. (Currently Amended) A method for computer workstation based 
information protection, the method comprising: 

a) monitoring a_user*s actions on said computer workstation, 

b) performing a statistical analysis of content in use by said user to 
identify confidential information in said content. 

6) analyzing analysis of said actions with j n-respect to a pre-defined 
policy associated with said identified confidential information, t o determine whether 
said actions prejudice said confidential informatio n to which said policy appli e s , and 

e)-d) executing said policy in accordance with the results of said analysis to 
control p r e v e nt — er — modify — of — restrict — ef — monitor — ef — leg — said actions. 

2. (Original) A method according to claim 1, wherein said policy 
comprises restrictions on at least one of the following actions: print, save, copy, 
autosave, fax. 

3. (Original) A method according to claim 1, wherein said monitoring 
said user*s actions on said workstation comprises detection of indications of attempts 
at tampering. 

4. (Original) A method according to claim 3, wherein said detection of 
indications of attempts at tampering comprises obtaining logical indications or 
statistical indications. 

5. (Original) A method according to claim 3, wherein said detection of 
indications of attempts of tampering comprises detection of at least one un-certified 
add-in. 
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6. (Original) A method according to claim 5, wherein said detection 
includes noting that said im-certified add-in is hooked to events of a local operating 
system. 

7. (Original) A method according to claim 3, wherein said detection of 
indications of attempts at tampering comprises detection of at least one debugging 
technique. 

8. (Original) A method according to claim 7, wherein said debugging 
technique comprises use of any of: a debugger, a virtual machine, a software emulator, 
a software trap, and a remote administration tool. 

9. (Original) A method according to claim 3, wherein said policy 
comprises restrictions of actions made available to said user upon said detection of 
indications of attempts of tampering. 

10. (Original) A method according to claim 9, wherein said restrictions of 
user's actions upon said detection of indications of attempts of tampering comprise 
applying restrictions on actions within a software application operable to process said 
information. 

11. (Original) A method according to claim 3, wherein said execution of 
said policy comprises performing at least one action upon detection of indications of 
attempts of tampering. 

12. (Original) A method according to claim 11, wherein said actions 
comprise at least one of the following: encrypting at least one buffer, and encrypting 
at least one shared memory. 
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13. (Original) A method according to claim 11, wherein said actions 
comprise preventing the decryption of encrypted digital content. 

14. (Original) A method according to claim 1, wherein said pre-defined 
policy is defined with respect to a software application on said user*s workstation. 

15. (Original) A method according to claim 1, wherein said policy 
comprises reporting about attempts to perform actions that do not comply with an 
organizational policy or about attempts to perform actions that are suspected to not 
comply with the organizational policy. 

16. (Original) A method according to claim 1, wherein said policy 
comprises performing logging of attempts to perform actions that that do not comply 
or are suspected to not comply with the organizational policy. 

17. (Original) A method according to claim 1, wherein said information 
protection comprises protecting information held within a software data processing 
application able to process said information. 

18. (Original) A method according to claim 17, wherein said software data 
processing application operates in conjimction with a software client. 

19. (Original) A method according to claim 17, wherein said software 
client is a tamper-resistant software client. 



20. (Original) A method according to claim 17, wherein said software 
client is operable to monitor said user's actions and to execute said policy. 
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21. (Original) A method according to claim 17, wherein said software 
client is operable to detect information based on statistical identifiers residing in a 
specialized database. 

22. (Original) A method according to claim 17, wherein said software 
client is fiarther operable to detect events of said software application. 

23. (Original) A method according to claim 22, wherein said events 
comprise events required for any of: printing said information; copying said 
information; storing said information, and displaying said information. 

24. (Original) A method according to claim 1, wherein said policy fiuther. 
comprising managing usage rights. 

25. (Original) A method according to claim 24, wherein said usage rights 
are determined according to any of: the classification of the document; the 
classification level of the user, and the authentication level of the user. 

26. (Original) A method according to claim 24, wherein said usage rights 
comprise any of: viewing at least part of said information; modifying at least part of 
said information; sending at least part of said information to a recipient; storing at 
least part of said information; storing at least part of said information by an 
application; storing at least part of said information by a file system; storing at least 
part of said information in a portable device; storing at least part of said information in 
a removable media; storing at least part of said information portable storage device 
that is connected to said workstation using a USB port; pasting at least part of said 
information into a document; printing at least part of said information; printing at least 
part of said information to file; printing at least part of said information to a fax, and 
printing a screen view document. 
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27. (Original) A method according to claim 24 wherein said policy further 
comprises definitions of actions to be performed. 

28. (Original) A method according to claim 27, wherein said actions 
comprise any of: enabling usage of at least part of said information; disabling usage of 
at least part of said information; restricting the usage of at least part of said 
information, according to a pre-determined set of restrictions; reporting about the 
usage of at least part of said information, and monitoring the usage of at least part of 
said information. 

29. (Original) A method according to claim 28, wherein said restriction of 
usage imposes requiring encryption of at least part of said protected information. 

30. (Original) A method according to claim 29, wherein said required 
encryption is such that corresponding encrypted information can be decrypted only by 
a secure client. 

31. (Original) A method according to claim 28, wherein said restriction of 
usage requires said protected information to reside on a secure server. 

32. (Original) A method according to claim 31, comprising arranging a 
coimection between said secure server and said workstation such that the transport 
between said secure server and said workstation is protected. 

33. (Original) A method according to claim 32, wherein said protected 
transport comprises an encrypted transport. 
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34. (Original) A method according to claim 29, wherein said encryption of 
protected information further comprising encryption of a file comprising at least part 
of said protected information wherein said file is at least one of the following: 
temporary file and auto-recovery file. 

35. (Original) A method according to claim 31, wherein said protected 
information fiirther comprises a file comprising at least part of said protected 
information, wherein said file comprises any of temporary file and auto-recover file. 

36. (Original) A method according to claim 17, wherein said software 
client authenticates itself to a server before at least some of the sessions. 

37. (Original) A method according to claim 36, wherein said authentication 
depends on a classification level assigned to said protected information. 

38. (Original) A method according to claim 36, wherein said authentication 
comprises any of: password based authentication; and network address based 
authentication. 

39. (Original) A method according to claim 17, wherein said software 
client comprises components that can be automatically replaced. 

40. (Original) A method according to claim 31, wherein said secure server 
employs cryptographic encryption of at least one file containing said protected 
information. 



41. (Original) A method according to claim 31, wherein communication 
with said server is substantially transparent to said user. 
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42. (Original) A method according to claim 17, wherein in accordance with 
said policy said protected information is encrypted utilizing the encryption capabilities 
of said software application. 

43. (Original) A method according to claim 42, wherein said software 
application operable to process said information is any of: a word processing 
application; Microsoft "word"; Open office "word", and Star office "word". 

44. (Original) A method according to claim 17, wherein said software 
application comprises a control flag imparting a status of either read only or lock to a 
corresponding file, and wherein file modification within said software application 
which is operable to process said information is disabled via said flag. 

45. (Original) A method according to claim 44, wherein said disabling of 
said file modification is controlled by said policy. 

46. (Original) A method according to claim 1, wherein said policy 
comprises adding forensic information to said protected information. 

47. (Original) A method according to claim 17, wherein said software 
client replaces the clipboard fimctionality of said software application thereby to 
process said protected information with a secure clipboard fimctionality. 

48. (Original) A method according to claim 47, wherein said protected 
information copied into said secure clipboard is stored in an intemal data structure 
inaccessible to other applications. 



49. (Original) A method according to claim 17, wherein said software 
client is installed automatically firom a remote server. 
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50. (Original) A method according to claim 49, wherein said installation of 
said software client utilizes anti-virus installation infrastructure. 

51. (Original) A method according to claim 17, wherein updates of said 
software client utilize anti-virus update infrastructure. 

52. (Original) A method according to claim 17, wherein at least part of the 
software code of said software client resides in an encrypted form. 

53. (Original) A method according to claim 17, wherein at least part of the 
software code of said software client is attached to hardware of said computer 
workstation. 

54. (Original) A method according to claim 17, wherein said software 
client is operable to automatically add information to said protected information in 
accordance with said policy. 

55. (Original) A method according to claim 54, wherein said added 
information comprises any of: a document header; a document footer; and a textual 
disclaimer. 

56. (Original) A method according to claim 17, wherein said client 
software is operable to open file that comprises said protected information only while 
connected to at least one server. 



57. (Original) A method according to claim 56, wherein said servers 
enforce a policy with respect to said protected information. 
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58. (Original) A method according to claim 57, wherein said policy implies 
a set of restrictions regarding the usage of the said protected information. 

59. (Original) A method according to claim 17, wherein said client 
software is operable to check that it is connected to a predetermined server before 
decrypting a file that comprise said protected information. 

60. (Original) A method according to claim 59, wherein said servers 
enforce a policy with respect to said protected information, and wherein said policy 
comprises a set of restrictions regarding the usage of the said protected information. 

61. (Original) A method according to claim 56, wherein at least two 
servers are operable to define said policy. 

62. (Original) A method according to claim 61, wherein, in the event of 
two or more conflicting policies being foxmd, a strictest one of the policies is 
identified and used. 

63. (Original) A method according to claim 62, wherein in the event of two 
or more conflicting policies being found, a policy comprising the xmion of restrictions 
of said policies is used. 

64. (Original) A method according to claim 56, wherein connection to at 
least two servers are required in order to determine said policy. 

65. (Original) A method according to claim 56, wherein said server 
authenticates the integrity of said client by requiring a cryptographic hash of at least 
part of said client's software. 
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66. (Original) A method according to claim 66, wherein said cryptographic 
hash is with respect to a random address in said clients software. 

67. (Original) A method according to claim 56, wherein said client is 
entangled with said server's software, such that a fimctioning stand-alone copy of said 
client's software does not exist. 

68. (Original) A method according to claim 56, wherein said method 
comprises at least two levels of protection, and wherein said levels of protection are 
operable to be configured as a function of the secrecy of said protected information. 

69. (Original) A method according to claim 68, wherein in the most secure 
of said levels of protection, said protected information can only be accessed while 
connected to said server. 

70. (Original) A method according to claim 68, wherein in at least one of 
said levels of protection, said information can be accessed for a limited time after the . 
connection with said server was terminated. 

71. (Original) A method according to claim 68, wherein in at least one of 
said levels of protection, said information can be accessed imtil the end of a current 
login session. 



72. (Original) A method according to claim 68, wherein in at least one of 
said levels of protection, said information can be xmlimitedly accessed after the server 
approves said information. 
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73. (Currently Amended) A method for information protection, said 
information comprising information items, said information being for usage on a 
computer workstation, comprising: 

a) defining an information protection policy with respect to an c e rtain 
information item^ 

b) determining the measures required to protect said information item 
according to said polic y, and 

c) performing a statistical analysis of content in use on said computer 
workstation to identify said information item, and 

de) allowing said usage on a computer workstation of content 
comprising said information comprising said item s for which an information 
protection policy is defin e d only while said required measures are being applied. 

74. (Original) A method according to claim 73, wherein said information 
protection measures comprises protecting information within a client software 
application. 

75. (Original) A method according to claim 74, wherein said protecting 
information within a client software application comprises disabling at least one of the 
controls of said application. 

76. (Original) A method according to claim 73, wherein said information 
protection measures comprises encryption of the memory of a graphic card or a video 
card. 

77. (Original) A method according to claim 73, wherein said information 
protection measures comprises forcing a video card or a graphic card to a mode that 
causes no meaningful information to be stored in said video card's memory. 
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78. (Original) A method according to claim 73, wherein said information 
protection measures comprises scanning at least one storage device and identifying the 
existence of pre-defined information objects. 

79. (Original) A method according to claim 78, wherein said pre-defined 
information objects comprise confidential information objects. 

80. (Original) A method according to claim 73, wherein said information 
protection policy comprises at least one rule regarding at least one event of at least one 
software application operable to handle said information. 

81. (Withdrawn) A method for information protection, said information 
comprising information items, said information being for presentation on a computer 
screen, comprising: a) defining an information protection policy with respect to 
certain information item b) determining the measures required to resist screen capture 
according to said policy c) allowing presentation of information comprising items for . 
which an information protection policy is defined on said computer screen only while 
said required measures are being applied. 

82. (Withdrawn) A method according to claim 81, wherein said measures 
comprise requiring typing a key-combination that forces the user to keep both hands 
on a keyboard. 

83. (Withdrawn) A method according to claim 81, wherein said measures 
comprise: a) attaching and connecting a digital video camera to said computer, said 
digital camera photographing the user; b) analyzing the output of said camera in order 
to determine that the user is looking at said computer screen; and c) presenting said 
protected information on said computer screen only while the user is looking at said 
computer screen. 
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84. (Withdrawn) A method according to claim 83, wherein said analysis of 
the output of said camera further allows to determine the part of said screen on which 
the eyes of said user are focused and said protected information appears only on the 
part of said screen on which the eyes of said user are focused. 

85. (Withdrawn) A method according to claim 83, wherein said analysis 
further allows to verify the identity of said user and said protected information is 
presented on said computer screen only after the identity of said user has been verified 
to be an identity of a user authorized to access said information. 

86. (Withdrawn) A method according to claim 83, comprising storing the ; » 
video sequence that is produced by said camera while the user is viewing said ^ 
information. 

87. (Withdrawn) A method according to claim 86, comprising storing said 
video sequence in a secure storage. 

88. (Withdrawn) A method according to claim 81, comprising setting the 
frame-rate of the screen in a maimer that is not synchronized with standard frame-rates 
of video cameras. 

89. (Withdrawn) A method according to claim 81, comprising dynamically 
changing the frame-rate of the screen. 



90. (Withdrawn) A method according to claim 81, wherein said measures 
comprise viewing said information being allowed only using a head-mounted display. 
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91. (Withdrawn) A method according to claim 81, wherein said measures 
comprise a sensor operable to detect that said user is wearing said head-mounted 
display, and wherein said protected information is presented on said screen only if 
said sensor has verified that said user is wearing said head-mounted display. 

92. (Withdrawn) A method according to claim 90, wherein said head- 
mounted display is equipped with a device operable to identify said user using a 
biometric feature. 

93. (Withdrawn) A method according to claim 92, wherein said protected 
information is presented on said head-mounted display only after said sensor has 
verified that said user identity is an identity of an user authorized to use said 
information. 

94. (Withdrawn) A method according to claim 91, wherein said measures 
comprise requiring usage of special glasses for viewing said information on said 
computer screen. 

95. (Withdrawn) A method according to claim 94, wherein said special 
glasses are equipped with shutters, said shutters being opened only when said 
information is displayed. 

96. (Withdrawn) A method according to claim 94, wherein at least part of 
said information is presented on said screen in certain, very short, time intervals, while 
other visual information is presented on said screen during other time intervals, in a 
manner operable to interfere with viewing said information without said glasses or 
with photographing the screen. 
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97. (Withdrawn) A method according to claim 94, wherein said 
information is presented on said screen in a maimer that can substantially be viewed 
only while using glasses operable to present 3 -dimensional image of said information 
presented on said screen. 

98. (Withdrawn) A method according to claim 94, wherein said measures 
comprise a sensor operable to detect that said user is wearing said glasses, and 
wherein said protected information is presented on said screen only if said sensor has 
verified that said user is wearing said glasses. 

99. (Withdrawn) A method according to claim 94, wherein said glasses are 
equipped with a device operable to identify said user using a biometric feature. 

100. (Withdrawn) A method according to claim 99, wherein said protected 
information is presented on said screen only after said sensor has verified that said 
user identity is an identity of an user authorized to use said information. 

101. (Withdrawn) A method according to claim 81, wherein said measures 
comprise at least one camera-detection sensor, operable to detect the presence of 
camera. 

102. (Withdrawn) A method according to claim 101, wherein said protected 
information is presented on said screen only after said sensor has substantially verified 
that no camera capable of taking screenshots of said screen exists in a position that 
allows taking screenshots of said screen. 

103. (Withdrawn) A method according to claim 81 wherein said measures 
comprise verifying that the screen on which said information is to be displayed is a 
screen that restricts the viewing angle. 
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104. (Withdrawn) A method according to claim 81, wherein said measures 
comprise constantly moving the protected information. 

105. (Withdrawn) A method according to claim 81, wherein said measures 
comprise displaying the text against a backgrovmd that is designed in a manner that 
effectively reduces the quality of a picture taken by a standard camera. 

106. (Withdrawn) A method according to claim 81, wherein said measures 
comprise requiring the usage of a LCD screen. 

107. (Currently Amended) A method for computer workstation based 
information protection, the method comprising: 

a) detecting an event occurring at said workstation, 

b) performing a statistical analysis of content associated with said event 
to identify confidential information vyithin said conten t dir e oting handling of said 
ev e nt , and 

c) employing information protection based on an assessment of an 
importance of said event to protection of said confidential informatio n indicat e d as 
r e quiring prot e ction t e chniqu e. 

108. (Original) A method according to claim 107, further comprising: 
handling an event, said event being designated as directing information protection, 
and employing a said information protection technique in reaction to said event. 

109. (Original) A method according to claim 108, wherein said event 
comprise any of: loading a local operating system; loading an application; user action; 
presenting a specific information into the system; an event generated by another 
system; suspicious activity; operating system time event; and a network time event. 
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110. (Currently Amended) A system for computer workstation based 
information protection, the system comprising: 

i) a monito r configured for monitoring a user's actions on said 
computer workstation; 

ii) an analyzer configured for performing a statistical analysis of a 
content in use bv said user to identify confidential information in said content and for 
analyzing said actions with i e-respect to a pre-defined policy associated with said 
confidential information t o determine whether said actions prejudice said information 
to which said policy applies , and 

iii) a policy execution module configured for executing said policy in 
accordance with the results of said analysis to control p r e v e nt or modify or restrict or 
monitor or log said actions. 




111. (Original) A system according to claim 110, wherein said policy 
comprises restrictions on at least one of the following actions: print, save, copy, 
autosave, fax. 

112. (Original) A system according to claim 110, wherein said monitoring 
said user's actions on said workstation comprises detection of indications of attempts 
at tampering. 

113. (Original) A system according to claim 1 12, wherein said detection of 
indications of attempts of tampering comprises detection of at least one im-certified 
add-in. 




114. (Original) A system according to claim 113, wherein said detection of 
indications of attempts at tampering comprises detection of at least one debugging 
technique. 
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115. (Original) A system according to claim 112, wherein said policy 
comprises restrictions of actions made available to said user upon said detection of 
indications of attempts of tampering. 

116. (Original) A system according to claim 115, wherein said restrictions 
of user's actions upon said detection of indications of attempts of tampering comprise 
applying restrictions on actions within a software application operable to process said 
information. 

117. (Original) A system according to claim 116, wherein said software data 
processing application operates in conjimction with a tamper-resistant software client. . 

118. (Original) A system according to claim 117, wherein said software , 
client is operable to monitor said user's actions and to execute said policy. 

119. (Original) A system according to claim 117, wherein said software 
client is operable to detect information based on statistical identifiers residing in a 
specialized database. 

120. (Original) A system according to claim 117, wherein said software 
client is further operable to detect events of said software application. 

121 . (Original) A system according to claim 110, wherein szdd policy fiirther 
comprising managing usage rights. 

122. (Original) A system according to claim 121, wherein said usage rights 
comprise any of: viewing at least part of said information; modifying at least part of 
said information; sending at least part of said information to a recipient; storing at 
least part of said information; storing at least part of said information by an 
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application; storing at least part of said information by a file system; storing at least 
part of said information in a portable device; storing at least part of said information in 
a removable media; storing at least part of said information portable storage device 
that is connected to said workstation using a USB port; pasting at least part of said 
information into a document; printing at least part of said information; printing at least 
part of said information to file; printing at least part of said information to a fax, and 
printing a screen view document. 

123. (Original) A system according to claim 117, wherein said client 
software is operable to check that it is connected to a predetermined server before 
decrypting a file that comprise said protected information only while connected to at^ 
least one server. 

124. (Original) A system according to claim 123, wherein said servers 
enforce a policy with respect to said protected information, and wherein said policy 
comprises a set of restrictions regarding the usage of the said protected information. 

125. (Original) A system according to claim 116, wherein said software 
application operable to process said information is any of: a word processing 
application; Microsoft "word". Open office "word", and Star office "word". 

126. (Original) A system according to claim 117, wherein said software 
client replaces the clipboard fimctionality of said software application thereby to 
process said protected information with a secure clipboard fimctionality. 



127. (Original) A system according to claim 117, wherein said software 
client is installed or updated automatically firom a remote server. 
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128. (Original) A system according to claim 127, wherein said installation 
or updates of said software client utilize anti-vims installation infirastmcture. 

129. (Original) A system according to claim 127, wherein said software 
client is operable to automatically add information to said protected information in 
accordance with said policy. 

130. (Original) A system for information protection, said information 
comprising information items, said information being for usage on a computer 
workstation, comprising: a) a policy reference monitor for defining an information 
protection policy with respect to certain information item and determining the 
measures required to protect said information according to said poUcy b) a policy 
execution module for allowing said usage on a computer workstation of information 
comprising said items for which an information protection policy is defined only 
while said required measures are being applied. 

131. (Withdrawn) A system for information protection, said information 
comprising information items, said information being for presented presentation on a 
computer screen, comprising: a) a policy reference monitor for defining an 
information protection policy with respect to an certain information item and 
determining the measures required to resist screen capture according to said policy b) 
a policy execution module for allowing presentation of information comprising items 
for which an information protection policy is defined on said computer screen only 
while said required measures are being applied. 



132. (Withdrawn) A system according to claim 131, wherein said measures 
comprise requiring typing a key-combination that forces the user to keep both hands 
on a keyboard. 
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133. (Withdrawn) A system according to claim 131, wherein said measures 
comprise: attaching and connecting a digital video camera to said computer, said 
digital camera photographing the user; analyzing the output of said camera in order to 
determine that the user is looking at said computer screen; and presenting said 
protected information on said computer screen only while the user is looking at said 
computer screen. 

134. (Withdrawn) A system according to claim 133, wherein said analysis 
further allows to verify the identity of said user and said protected information is 
presented on said computer screen only after the identity of said user has been yerified 
to be an identity of a user authorized to access said information. 

135. (Withdrawn) A system according to claim 133, comprising storing the 
video sequence that is produced by said camera while the user is viewing said 
information. 

136. (Withdrawn) A system according to claim 131, comprising setting the 
frame-rate of the screen in a manner that is not synchronized with standard frame-rates 
of video cameras. 

137. (Withdrawn) A system according to claim 131, comprising 
dynamically changing the frame-rate of the screen. 

138. (Withdrawn) A system according to claim 131, wherein said measures 
comprise viewing said information being allowed only using a head-mounted display. 



139. (Withdrawn) A system according to claim 131, wherein said measures 
further comprise a sensor operable to detect that said user is wearing said head- 
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mounted display, and wherein said protected information is presented on said screen 
only if said sensor has verified that said user is wearing said head-mounted display. 

140. (Withdrawn) A system according to claim 139, wherein said head- 
mounted display is equipped with a device operable to identify said user using a 
biometric feature. 

141. (Withdrawn) A system according to claim 131, wherein said measures 
comprise requiring usage of special glasses for viewing said information on said 
computer screen. 

142. (Withdrawn) A system according to claim 141, wherein at least part of 
said information is presented on said screen in certain, very short, time intervals, while 
other visual information is presented on said screen during other time intervals, in a 
manner operable to interfere with viewing said information without said glasses or 
with photographing the screen. 

143. (Withdrawn) A system according to claim 131, wherein said measures 
comprise at least one camera-detection sensor, operable to detect the presence of 
camera. 

144. (Withdrawn) A system according to claim 143, wherein said protected 
information is presented on said screen only after said sensor has substantially verified 
that no camera capable of taking screenshots of said screen exists in a position that 
allows taking screenshots of said screen. 



145. (Withdrawn) A system according to claim 131, wherein said measures 
comprise constantly moving the protected information. 
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146. (Withdrawn) A system according to claim 131, wherein said measures 
comprise displaying the text against a background that is designed in a maimer that 
effectively reduces the quality of a picture taken by a standard camera. 

147. (New) A method according to claim 1, wherein controlling a user's 
action comprises at least one of: preventing said action, modifying said action, 
restricting, said action, monitoring said action, or logging said action. 

148. (New) A system according to claim 110, wherein to control an action 
comprises at least one of: preventing said action, modifying said action, restricting, 
said action, monitoring said action, or logging said action. 
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